imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2014-6416
High 7.8

Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.

canonical ubuntu_linux · linux linux_kernel
0.06EPSS
CVE-2006-1858
High 7.8

SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.

linux linux_kernel
0.06EPSS
CVE-2012-3412
High 7.8

The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.

canonical ubuntu_linux · linux linux_kernel
0.06EPSS
CVE-2023-2156
High 7.5

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remot…

debian debian_linux · fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.06EPSS
CVE-1999-0590
High 10.0

A system does not present an appropriate legal message or warning to a user who is accessing it.

apple macos · linux linux_kernel · microsoft windows_2000 · microsoft windows_95 · and 2 more
0.06EPSS
CVE-2020-8835
High 7.8

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable s…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · netapp 8300_firmware · and 23 more
0.06EPSS
CVE-2006-1368
High 10.0

Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc'd memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocate…

linux linux_kernel
0.06EPSS
CVE-2017-6074
High 7.8

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via…

debian debian_linux · linux linux_kernel
0.06EPSS
CVE-2014-4667
Medium 5.0

The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · suse linux_enterprise_desktop · and 2 more
0.06EPSS
CVE-2017-7645
High 7.5

The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.06EPSS
CVE-2009-4537
High 7.8

drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet …

debian debian_linux · linux linux_kernel
0.06EPSS
CVE-2022-2588
Medium 5.3

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

canonical ubuntu_linux · linux linux_kernel
0.06EPSS
CVE-2015-4003
High 7.8

The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via a crafted packet.

linux linux_kernel
0.06EPSS
CVE-2014-3688
Medium 5.0

The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/i…

linux linux_kernel
0.06EPSS
CVE-2019-8980
High 7.5

A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap
0.06EPSS
CVE-2011-3188
Critical 9.1

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking…

f5 arx · f5 big-ip_access_policy_manager · f5 big-ip_analytics · f5 big-ip_application_security_manager · and 11 more
0.06EPSS
CVE-2014-5077
High 7.1

The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association bet…

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux_eus · redhat enterprise_linux_server_aus · and 4 more
0.06EPSS
CVE-2019-11810
High 7.5

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a use-after-…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.06EPSS
CVE-2020-24586
Low 3.5

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another dev…

arista c-200_firmware · arista c-230_firmware · arista c-235_firmware · arista c-250_firmware · and 20 more
0.06EPSS
CVE-2020-12352
Medium 6.5

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

linux linux_kernel
0.06EPSS
CVE-2011-2699
High 7.5

The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values a…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_mrg
0.06EPSS
CVE-2016-4997
High 7.8

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root a…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell suse_linux_enterprise_desktop · and 7 more
0.06EPSS
CVE-2016-9919
High 7.5

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.

linux linux_kernel
0.06EPSS
CVE-2019-9213
Medium 5.5

In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for the w…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap · and 1 more
0.06EPSS
CVE-2019-3846
High 8.8

A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 8 more
0.06EPSS